๐Ÿ” CVE Alert

CVE-2026-73055

MEDIUM 4.8

Shescape before 2.1.15 Home Directory Disclosure via BusyBox

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.

CWE CWE-116
Vendor ericcornelissen
Product shescape
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for ericcornelissen shescape

Be the first to know when new medium vulnerabilities affecting ericcornelissen shescape are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

ericcornelissen / shescape
0 < 2.1.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j44h-fqhh-fh28 github.com: https://github.com/ericcornelissen/shescape/commit/d86bf2ae22961c73458bddf70dd06adf9dadb36c github.com: https://github.com/ericcornelissen/shescape/commit/7cba30594c16a21524706efe2f6c6c9d8923f411 vulncheck.com: https://www.vulncheck.com/advisories/shescape-before-home-directory-disclosure-via-busybox

Credits

๐Ÿ” alimony ericcornelissen